Skip to content

Deploy the self-managed PostgreSQL template with OpenTofu

Deployment · Updated Jun 2026

Coming from another cloud?

▸AWS·RDS Postgres

This Quake AI feature maps to AWS’s RDS Postgres.

▸DigitalOcean·Managed DB

This Quake AI feature maps to DigitalOcean’s Managed DB.

▸Google Cloud·Cloud SQL

This Quake AI feature maps to Google Cloud’s Cloud SQL.

Deploy the self-managed PostgreSQL template with OpenTofu

Stand up PostgreSQL 16 on a private subnet with a dedicated Cinder data volume using the validated OpenTofu template self-managed-postgres. The database listens on a private address only; cloud-init formats the data volume at /var/lib/postgresql, enables WAL archiving, and installs a scheduled pg_dumpall backup script.

Monthly cost estimate

Pricing calculator ↗

Sized as a custom package on dedicated vCPU.

Starting template$132.60/mo

Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.

What each resource is for

PostgreSQL database

m2a.xlarge · 4 dedicated vCPU, 16 GiB RAM, 1 Gbps

$132.00/mo

Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.

Included in baseline

m2a.xlarge

4 dedicated vCPU, 16 GiB RAM, 1 Gbps

$132.00

Compute + RAM rate basis

4 vCPU + 16 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.

—

Block storage (70 GiB)

70 GiB at $0.08/GiB/mo

$5.60

Package promotional discount

Flat −$5.00/mo on the custom package (same promotion as named plans).

$-5.00

Included at no charge

These line items are zero on Quake AI. Many other providers meter them separately.

Data transfer (inbound and outbound)

Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.

AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.

Learn more
$0.00

Private networking

Private networks, subnets, Neutron routers, and security groups are included with the plan.

VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.

$0.00

Control-plane API requests

OpenStack API calls for provisioning and management are included.

Some managed services on other clouds meter API calls or charge for premium control-plane features.

$0.00

Dev/test vs production

Start on shared CPU for dev/test, then promote to dedicated for production with a flavor resize. The network, storage, and template stay the same.

Dev/test on shared CPU

Burstable s1a flavors; suited to prototyping and low or bursty load.

$33.60/mo

Production on dedicated CPU

The headline estimate above; predictable steady-load performance.

$132.60/mo

Saves $99.00/mo while you build on shared CPU.

Shared flavors carry less RAM (m2a.xlarge (16 GiB RAM) -> s1a.medium (4 GiB RAM)). A resize reboots the instance; data on attached volumes persists. Size the dedicated flavor for the RAM your production workload needs.

Pricing data last validated: . For current rates, check quake.ai/pricing.

Quake AIRouterto PublicStaticPrivate network192.168.40.0/24Block volume50 GB/var/lib/postgresqlSecurity groupSSH + PostgreSQLpgPostgreSQL 16port 5432 /dev/sdb
Click to zoom
Self-managed PostgreSQL topology: private network, PostgreSQL instance on a dedicated data volume, router to PublicStatic, no floating IP

Prerequisites#

You need:

Step 1: Configure variables#

Copy terraform.tfvars.example to terraform.tfvars and set:

HCL
key_name      = "YOUR_KEY_NAME"
allowed_cidrs = ["192.168.40.0/24"]
db_password   = "CHOOSE_A_STRONG_PASSWORD"
VariablePurpose
key_nameExisting SSH key pair name Nova uses at boot
allowed_cidrsIPv4 ranges that may connect to PostgreSQL on port 5432
db_passwordPassword cloud-init assigns to appuser

Defaults for flavor, volume size, PostgreSQL version, and network CIDR are documented on the Self-Managed PostgreSQL reference page.

Step 2: Apply the template#

From the template directory, run:

bash
tofu init
tofu plan
tofu apply

Type yes when prompted. Provisioning takes several minutes while Nova builds the boot volume, Cinder provisions the data volume, and cloud-init formats /dev/sdb and installs PostgreSQL.

When the run finishes, note private_ip from the outputs.

Step 3: Verify PostgreSQL and the data volume#

Cloud-init can take a few more minutes after tofu apply returns. SSH to the instance private IP from a host that routes to the subnet:

bash
PRIVATE=$(tofu output -raw private_ip)
ssh -i ~/.ssh/YOUR_KEY ubuntu@${PRIVATE}

On the instance, confirm the data volume is mounted and PostgreSQL is running:

bash
df -h /var/lib/postgresql
sudo systemctl is-active postgresql
sudo -u postgres psql -c "\l" | grep appdb

Connect as the application user and run a test query:

bash
PGPASSWORD='CHOOSE_A_STRONG_PASSWORD' psql -h 127.0.0.1 -U appuser -d appdb -c "CREATE TABLE deploy_check (id int); INSERT INTO deploy_check VALUES (1); SELECT * FROM deploy_check;"

The query returns one row, which confirms PostgreSQL stores data on the attached volume.

Optional: confirm WAL archiving and the backup cron:

bash
sudo -u postgres psql -c "SHOW archive_mode;"
ls -l /usr/local/bin/pg-backup.sh /etc/cron.d/pg-backup

Next steps#

Clean up#

Run tofu destroy from the project directory when finished. Type yes to confirm. Verify in the Console that the instance and data volume are gone.

Was this page helpful?